URLhaus Database

You are currently viewing the URLhaus database entry for http://maxscrew.ir/wp-includes/statement/xmyeo790t7dno/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:734375
URL: http://maxscrew.ir/wp-includes/statement/xmyeo790t7dno/
URL Status:Offline
Host: maxscrew.ir
Date added:2020-10-22 11:52:07 UTC
Last online:2020-11-26 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 11:54:08 UTC to report{at}parspack[dot]com)
Takedown time:1 month, 4 days, 21 hours, 2 minutes Bad (down since 2020-11-26 08:56:28 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22BAL_RBC_100120_NNL_102220.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdn/aHeodo
2020-10-22FDL_100120_PHS_102220.docdoc 03d580e7110bd85d7a360ceb31538a967f59877402892ca04ae4859e4ea20e00Virustotal results 42.31%Heodo
2020-10-22OZB_100120_KUM_102220.docdoc dc0ef0bf48199eb407cb13b8506149dd5ecb392ee2682edc318b58f5d1dac769Virustotal results 43.55%Heodo
2020-10-22BAL_37365751042303.docdoc 892a53376594e2bdf65731771d6e7faa4d36e2d3b95340ac4984ec74536d3604Virustotal results 41.94%Heodo
2020-10-22F_PA8528359102WZ.docdoc e9d87e6f00f59e3b84a5389f77adc3ce03b38559a26aee1be20f6bf5c00e76fen/aHeodo
2020-10-22FILE_478238985799.docdoc 937c87496e98fe97075f0ae5ec35a64a75cc04b533f0a1a937d8a50096183519Virustotal results 41.94%Heodo
2020-10-22OM33Z9Z.docdoc c4d6c72ac1f2925c2af592fd65e1bbdfd5327d959321403faf797ec85d658a6fVirustotal results 38.18%Heodo
2020-10-22REP_Y3T2SHC4WZ3DYTC4.docdoc 28061fbdc60d3031a20e1c8f75d20d703307a03ba696fc87e507c3a356e0ae68Virustotal results 37.74%Heodo
2020-10-22PO_10222020EX.docdoc 0b9036fd0fb6b0170883b15323d34e278388c2ee3e9639f5341c44b7cc9f3403Virustotal results 38.89%Heodo
2020-10-22XV5166454066TT.docdoc cda2a4d05c53cff76ef32a29480efec51818dc2f26b02999980a33f1051d732bVirustotal results 40.32%Heodo
2020-10-22FILE_99235607.docdoc fa80d9c5ac5a3d08f91d1d1a13ca9e8dc5bd6e9dc289fa203b6822c74a1dbab9Virustotal results 38.33%Heodo
2020-10-22REP_18JSE5RF1GDNBE.docdoc 5071f2da34845b41b8e65266293f6756c12aef537eaa3777eeb4f6333f6191d5Virustotal results 36.54%Heodo
2020-10-22UYD_100120_MML_102220.docdoc 7bf5865edd1cf7fbc77de4691736ab60bb0d5163db0f3153bb804de1d88953feVirustotal results 38.60%Heodo
2020-10-22INV_PO_10222020EX.docdoc b02d8914188d8c0628510d4008fda2cb9854c383c714ccfec3133edf22263fe0Virustotal results 52.83% Heodo
2020-10-22REP_0285671577603722773.docdoc 98a7403f2284947cdcc0c179ba703329edb0e717b26a20be473a2c606a8abab6Virustotal results 49.12%Heodo
2020-10-2236054253.docdoc 15617c0893da95a3d6a9ef0767194dcdba28768fb1cb5bdd12b8321f99f7b970Virustotal results 50.00%Heodo
2020-10-22REP_734513304293824.docdoc 7672ae3ab7ee30ee3ef086ec0b9ced8c85e56d045f12305531d826ba491237b2n/aHeodo
2020-10-2200173599588123.docdoc 69246d46d3c893a3ee3740f371c6d72698daa05ba77e3dd8a2c9a4aaaf86aab7n/aHeodo
2020-10-22BAL_VK1668852985GC.docdoc e093c016746d804ab3f83b9ae5da804217da67e5038a0b3b77230d830623b560Virustotal results 43.33%Heodo
2020-10-22UCBB_SBM_100120_PZR_102220.docdoc 7eaf0df9dd2a33ee958384a9472366f58f1c0a204360efea6a7f8b0d298560d0Virustotal results 45.00%Heodo
2020-10-22DOC_PO_10222020EX.docdoc a3a0cc50da6331891009253878be3d1a6525255acc59600fb3aedc6066c1f5e9Virustotal results 43.33%Heodo